In Minecraft mod "Command Block IDE" up to and including version 0.4.9, a missing authorization (CWE-862) allows any user to modify "function" files used by the game when installed on a dedicated server.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-48645.json"
"2026-04-12T09:58:16Z"
[
{
"signature_version": "v1",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"97843601424127875611163910378090101914",
"310412983789645104390551920448770137459",
"161427845890154518230008909379077080649",
"98593900381224569537303768896576013514"
]
},
"source": "https://github.com/arm32x/command-block-ide/commit/42e09840168d9c2fe2ee07f4472d296000b2a416",
"id": "CVE-2024-48645-63bdce13",
"signature_type": "Line",
"target": {
"file": "src/main/java/arm32x/minecraft/commandblockide/CommandBlockIDE.java"
}
},
{
"signature_version": "v1",
"deprecated": false,
"digest": {
"length": 1080.0,
"function_hash": "281022893790334313340037953605720949716"
},
"source": "https://github.com/arm32x/command-block-ide/commit/42e09840168d9c2fe2ee07f4472d296000b2a416",
"id": "CVE-2024-48645-a8800020",
"signature_type": "Function",
"target": {
"function": "onInitialize",
"file": "src/main/java/arm32x/minecraft/commandblockide/CommandBlockIDE.java"
}
}
]